Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-28318 | SolarWinds | Serv-U | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. | 7.5 CNA | 2026-06-05 | 2026-06-19 | Unknown |
| CVE-2025-26399 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. | 9.8 CNA | 2026-03-09 | 2026-03-12 | Known |
| CVE-2025-40536 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Security Control Bypass Vulnerability SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. | 8.1 CNA | 2026-02-12 | 2026-02-15 | Unknown |
| CVE-2025-40551 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | 9.8 CNA | 2026-02-03 | 2026-02-06 | Unknown |
| CVE-2024-28987 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Hardcoded Credential Vulnerability SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data. | 9.1 CNA | 2024-10-15 | 2024-11-05 | Unknown |
| CVE-2024-28986 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution. | 9.8 CNA | 2024-08-15 | 2024-09-05 | Unknown |
| CVE-2024-28995 | SolarWinds | Serv-U | SolarWinds Serv-U Path Traversal Vulnerability SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine. | 8.6 CNA | 2024-07-17 | 2024-08-07 | Unknown |
| CVE-2021-35247 | SolarWinds | Serv-U | SolarWinds Serv-U Improper Input Validation Vulnerability SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization. | 4.3 CNA | 2022-01-21 | 2022-02-04 | Unknown |
| CVE-2016-3643 | SolarWinds | Virtualization Manager | SolarWinds Virtualization Manager Privilege Escalation Vulnerability SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-35211 | SolarWinds | Serv-U | SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. | 9.0 CNA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2020-10148 | SolarWinds | Orion | SolarWinds Orion Authentication Bypass Vulnerability SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |